Vmware · Edgeconnect Sd-Wan Orchestrator · CVE-2025-37181
**Name of the Vulnerable Software and Affected Versions**
EdgeConnect SD-WAN Orchestrator (affected versions not specified)
**Description**
The web-based management interface contains flaws that permit an authenticated remote attacker to conduct SQL injection attacks. Exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially resulting in unauthorized data access or manipulation.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.